Filevine

Security Compliance Analyst

Filevine$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computing or related field
  • 4+ years in IT Auditing or Compliance Analysis
  • Strong attention to detail in IT Audit & Risk Assessment
  • Familiarity with OWASP Top 10
  • Experience managing risks and security threats
  • Knowledge of web technologies and protocols
  • Experience with ISO/IEC compliance standards

Responsibilities

  • Manage CJIS obligations and conduct related audits
  • Assist with federal and international security audits
  • Help ensure compliance with HIPAA, SOC 2, among others
  • Collaborate with teams to adopt security best practices
  • Train employees on secure coding techniques
  • Address and resolve compliance and risk issues
  • Develop audit frameworks and risk methodologies

Benefits

  • Dynamic and growth-oriented company environment
  • Comprehensive Medical, Dental, and Vision Insurance
  • Maternity and paternity leave policies
  • Short & long-term disability coverage
  • Opportunities for learning and mentorship from leadership
  • Access to branded company merchandise
Full Job Description


Department Statement

The IT Audit team is responsible for performing timely audits and ensuring compliance and risk assessment efforts are aligned with industry standards and best practices.

Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels thus protecting and enhancing customer trust. If you are bright, hardworking, ambitious, and enjoy taking ownership of security and compliance, we want to talk to you. This is an exciting opportunity to join a world-class team.

Responsibilities:

  • Manage CJIS obligations, including monthly and yearly audits, clearances for employees, and associated CJIS efforts
  • Assist with Federal and international government security audits (e.g. FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs.
  • Assist with security efforts to meet HIPAA, SOC 2 Type I & II, and other compliance requirements.
  • Work directly with Information Security, Legal, HR, Compliance and Development teams to ensure secure IT and IS best practices are fully adopted at Filevine.
  • Help train employees on auditing secure coding techniques to mitigate the need for break-fix/out-of-band patching.
  • Review audit, compliance and risk assessment issues that arise and manage them to resolution.
  • Provide audit frameworks and risk assessment methodologies contemplating new software solutions to help mitigate security vulnerabilities and other business risks.
  • Maintain documented Policy and Procedure libraries for compliance purposes.
  • Complete Third-party vendor risk management and security questionnaires for Filevine.
  • Provided annual Internal audit and risk assessment functions.
  • Facilitate and lead annual penetration testing and auditing efforts.
  • Develop a familiarity with new auditing and risk assessment tools and techniques.


Qualifications:

  • Bachelor's Degree or equivalent in Computer Science, Computer Engineering, Information Technology, or related field
  • 4+ years of experience in IT Auditing, Compliance Analysst and/or direct experience related to risk assessment methodologies.
  • Proven work experience as IT Audit & Risk Assessor with a passion for details and security.
  • Familiarity with auditing and assessing the OWASP Top 10.
  • Experience with managing risks, fraud, and security threats.
  • Knowledge of web related technologies (Web applications, Web Services and Service Oriented Architectures, Web Databases) and of network/web related protocols.
  • Experience assessing, testing, or auditing technical IT and security controls.
  • Working knowledge of and demonstrated experience with ISO 27701, ISO 27018, ISO 27001
  • Experience with FedRAMP is preferred, as well as SOC II Type I & II, HIPAA Security Rule, CJIS, GDPR, CCPA/CPRA and other compliance frameworks.
  • Demonstrated knowledge of assessing development methodologies (Agile, Waterfall).
  • Ability to work in a fast-paced environment.
  • Must exhibit excellence in partnering, teamwork, and quality performance.
  • Able to effectively give, receive, and respond to feedback.
  • Excellent oral and written communication skills with the ability to communicate security concepts to a technical and non-technical audience including senior management.
  • Demonstrated ability to establish relationships and build rapport to influence colleagues at all levels, uncover issues, and identify needs.
  • This will be a hybrid schedule position ( 3/2 or 4/1 - TBD)


Preferred Qualifications:

  • Significant experience with auditing frameworks, formal audits, and risk assessment experience.
  • Significant experience with automated auditing and compliance tools.
  • GRC tool Certification or equivalent experience.
  • CISSP Certification or equivalent experience.
  • CISM Certification or equivalent experience.
  • CISA Certification or equivalent experience.
  • CIPP/US Certification or equivalent experience.
  • CRISC Certification or equivalent experience.


Cool Company Benefits:

- A dynamic, rapidly growing company, focused on helping organizations thrive

- Medical, Dental, & Vision Insurance (for full-time employees)

- Competitive & Fair Pay

- Maternity & paternity leave (for full-time employees)

- Short & long-term disability

- Opportunity to learn from a dedicated leadership team

- Top-of-the-line company swag

Privacy Policy Notice

Filevine will handle your personal information according to what's outlined in our Privacy Policy.

Communication about this opportunity, or any open role at Filevine, will only come from representatives with email addresses using "filevine.com". Other addresses reaching out are not affiliated with Filevine and should not be responded to.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

About Filevine

Filevine is a technology company that specializes in software and services. The company was founded in 2015 and is headquartered in Salt Lake City, Utah. Filevine provides a range of services, including case management, document management, and communication tools. The company's clients include law firms, insurance companies, and other businesses that require legal services. Filevine is known for its innovative approach to case management and its commitment to delivering high-quality products and services.
Learn more about Filevine
Size
200 employees
Industry
Net Income
$1 million
Founded
2015
5 Year Trend
+40%
Revenue
$20 million
NASDAQ

Similar Jobs

More Jobs at Filevine

More Information Technology Jobs

Find similar Security Compliance Analyst jobs: